Lucy™

Platform — Lucy Frontline

Security, data protection and compliance.

We publish what we have, and name what we don't. No forms, and no gaps left for you to discover on a call.

01 / 04

Information security

Infrastructure

The application tier runs in Frankfurt (DigitalOcean App Platform) and the data platform in Ireland (Supabase, eu-west-1). Traffic is encrypted in transit (HTTPS/WSS) and the managed data platform encrypts data at rest. Application containers are ephemeral and persist no customer data.

Access and authentication

Production administration is limited to two named engineers, with MFA enforced across the infrastructure organisations. Tenant isolation combines server-side logic, database Row Level Security, private storage policies and automated tests verifying that one tenant is denied access to another's data.

Backup and recovery

The production database has point-in-time recovery with a seven-day window. An important limitation is disclosed under “What we don't publish yet”.

Incident handling

Affected customers are notified as soon as reasonably possible after material impact is identified, subject to stricter contractual or legal requirements.

Documents

  • ↓Technical and organisational measures

02 / 04

AI and worker data

Lucy Frontline's AI features are bounded tools — task analysis, import extraction, avatars and translation. They do not evaluate employee work performance, never grant permissions and make no decisions about employees.

Employee-import output is always human-reviewed, and the prompt contract prohibits invented contact details, roles and permissions. Execution logs record provider, model, feature and outcome — never raw prompt content or raw model responses.

Today's provider endpoints (OpenAI, Google Translation) are global — we do not claim EU-only processing. OpenAI does not use API data for training by default; abuse monitoring may retain content up to 30 days. EU endpoints are planned, as is an open-model option on Swedish infrastructure for customers with such requirements. Providers may change within the contracted processing region; changing the contracted region requires your agreement.

Documents

  • ↓Technical documentation — AI-assisted features

03 / 04

Sub-processors

Lucy Frontline's sub-processors: Supabase (data platform, Ireland) · DigitalOcean (application hosting, Frankfurt) · OpenAI (AI features, global endpoint) · Google Cloud (translation) · Sentry (error monitoring, ingested in Germany) · 46elks (SMS, Sweden) · Resend (email — note the provider stores account data and metadata in the US). A DPA is available; the sub-processor schedule is being updated for Lucy Frontline and is provided on request.

Documents

  • ↓Sub-processor list

04 / 04

What we don't publish yet

We do not publish the following today, because it is not done — and a reviewer should hear it from us first

Files in object storage are not covered by database point-in-time recovery — a deleted file cannot be restored. Separate file backup is work in progress.

Independent certification · External penetration test · Contractual availability level (SLA) · Completed disaster-recovery exercise (runbook in progress) · Updated sub-processor schedule (in progress)

For your review team

A dated security and privacy pack — hosting details, backup evidence, administrator list, AI provider inventory, DPA and sub-processor register — is provided on request during evaluation. All platform pages are open: no email gate, no forms.

contact@lucyanalytics.com

This page is supporting material and process knowledge, not legal advice. Your own counsel is responsible for the assessment in each individual case.

Last verified: 2026-08-11. This page is updated when the facts change — not the other way around.